A vulnerability identified as critical has been detected in Hashmes Hash Form Plugin up to 1.4.2 on WordPress. The affected element is an unknown function. The manipulation leads to unrestricted upload. This vulnerability is traded as CVE-2026-81780. It is possible to initiate the attack remotely. There is no exploit available.
WordPress
Vulnerability
CVE-2026-81780
VulDB
Apply vendor security patch